Volution clients 1.0.7 and earlier attempt to contact the computer creation daemon (CCD) when an LDAP authentication failure occurs, which allows remote attackers to fully control clients via a Trojan horse Volution server.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Volution | Caldera | 1.0 (including) | 1.0 (including) |
Volution | Caldera | 1.0.6 (including) | 1.0.6 (including) |
Volution | Caldera | 1.0.7 (including) | 1.0.7 (including) |